Explains the configuration option that prevents endpoints within an EPG from communicating with each other.
Intra-EPG isolation enforcement is a security feature that
-
prevents endpoints within an EPG from communicating with each other
-
applies to all endpoints within an application EPG when configured, and
-
does not affect contracts that enable endpoints to communicate with endpoints in another EPG.
Configuration and support information
By default, endpoints with an EPG can communicate with each other without any contracts in place. However, you can isolate endpoints within an EPG from each other. For example, you may want to enforce endpoint isolation within an EPG to prevent a VM with a virus or other problem from affecting other VMs in the EPG.
You can configure isolation on all or none of the endpoints within an application EPG; you cannot configure isolation on some endpoints but not on others.
Enforcing intra-EPG Isolation is not supported for the EPG that is associated with Cisco ACI Virtual Edge domains in VLAN mode. If you try to enforce intra-EPG isolation with such an EPG, a fault is triggered.
Using intra-EPG isolation on a Cisco ACI Virtual Edge microsegment (uSeg) EPG is not currently supported.
Proxy ARP is not supported for Cisco ACI Virtual Edge EPGs using VXLAN encapsulation and on which intra-EPG Isolation is enforced. Therefore, intra-subnet communication is not possible between intra-EPG isolated EPGs even though contracts are in place between those Cisco ACI Virtual Edge EPGs. (VXLAN).
- Configure Intra-EPG Isolation for Cisco ACI Virtual Edge Using the GUI
Isolates endpoints within an EPG from each other using the Cisco APIC GUI. - Choose statistics for isolated endpoints on Cisco ACI Virtual Edge Under the Tenants Tab
Configures statistics selection for isolated endpoints on a Cisco ACI Virtual Edge to enable viewing of connection and packet data. - View Statistics for Isolated Endpoints on Cisco ACI Virtual Edge Under the Tenants Tab
View statistics for isolated endpoints that you have configured on a Cisco ACI Virtual Edge using the Cisco APIC Tenants tab. - Choose statistics for isolated endpoints on Cisco ACI Virtual Edge under the virtual networking tab
Configures statistics for isolated endpoints on a Cisco ACI Virtual Edge to monitor metrics such as denied connections, received packets, or transmitted multicast packets. - View statistics for isolated endpoints on Cisco ACI Virtual Edge under the Virtual Networking tab
Displays statistics for isolated endpoints on Cisco ACI Virtual Edge after configuring intra-EPG isolation and selecting statistics. - Configure Intra-EPG Isolation for Cisco ACI Virtual Edge Using the NX-OS Style CLI
Enables isolation mode for an EPG on the Cisco ACI Virtual Edge using the NX-OS style CLI. This configuration restricts communication between endpoints within the same EPG.